Vulnerability Note VU#512705
Broadcom NetXtreme management firmware ASF buffer overflow
Overview
A buffer overflow vulnerability exists in the Broadcom NetXtreme management firmware. This vulnerability may allow a remote attacker to execute arbitrary code on an affected device.
Description
The Alert Standard Format (ASF) Specification is a protocol developed by Distributed Management Task Force, Inc. (DMTF) that defines remote control and alerting interfaces for systems and devices when a host operating system is not present. The management firmware supplied with certain Broadcom NetXtreme network adapters supports ASF. A buffer overflow vulnerability exists in certain versions of this firmware when handling malformed ASF version 2.0 RAKP Message 1 packets. Devices with affected versions of the firmware would only be vulnerable if Remote Management and Control Protocol (RMCP) over the RMCP Security-Extensions Protocol (RSP) manageability is enabled. This functionality is typically disabled by default.
Broadcom notes that reliable exploitation of this vulnerability is specific to the device type and firmware version in use on the target system. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary or chosen code on the embedded management controller or cause the controller to halt operation, resulting in a denial of service. |
Solution
Apply an update from the vendor |
Disable ASF support
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Broadcom | Affected | - | 25 Mar 2010 |
| Hewlett-Packard Company | Affected | - | 18 Mar 2010 |
| Dell Computer Corporation, Inc. | Unknown | 25 Mar 2010 | 25 Mar 2010 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.ssi.gouv.fr/site_article185.html
- http://www.certa.ssi.gouv.fr/site/CERTA-2010-AVI-121/index.html
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02048471
Credit
Thanks to Rob Swindell of Broadcom for reporting this vulnerability. Broadcom credits Loïc Duflot, Yves-Alexis Perez of the French Agence Nationale de la Sécurité des Systèmes d’Information (ANSSI) with reporting this issue.
This document was written by Chad R Dougherty.
Other Information
- CVE IDs: CVE-2010-0104
- Date Public: 15 Mar 2010
- Date First Published: 25 Mar 2010
- Date Last Updated: 21 Jun 2010
- Severity Metric: 0.68
- Document Revision: 30
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.